VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,267)

page 425 of 464
  • CVE-2021-20283MedMar 15, 2021
    risk 0.21cvss 4.3epss 0.01

    The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2020-27057LowDec 15, 2020
    risk 0.21cvss 3.3epss 0.00

    In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure of gpu statistics with User execution privileges needed. User interaction is not needed for…

  • CVE-2020-27056LowDec 15, 2020
    risk 0.21cvss 3.3epss 0.00

    In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of package metadata with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID:…

  • CVE-2020-0459LowDec 14, 2020
    risk 0.21cvss 3.3epss 0.00

    In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with no additional execution privileges…

  • CVE-2020-2313MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Azure Key Vault Plugin 2.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2020-2311MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins AWS Global Configuration Plugin 1.5 and earlier allows attackers with Overall/Read permission to replace the global AWS configuration.

  • CVE-2020-2310MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins Ansible Plugin 1.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2020-2309MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing/An incorrect permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2020-2308MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Kubernetes Plugin 1.27.3 and earlier allows attackers with Overall/Read permission to list global pod template names.

  • CVE-2020-2306MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.

  • CVE-2020-2302MedNov 4, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Active Directory Plugin 2.19 and earlier allows attackers with Overall/Read permission to access the domain health check diagnostic page.

  • CVE-2020-15245MedOct 19, 2020
    risk 0.21cvss 4.3epss 0.01

    In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email [email protected], verify it, change it to the mail [email protected] and stay verified and enabled. This may lead to having accounts addressed to totally different emails, that were…

  • CVE-2020-0412LowOct 14, 2020
    risk 0.21cvss 3.3epss 0.00

    In setProcessMemoryTrimLevel of ActivityManagerService.java, there is a missing permission check. This could lead to local information disclosure of foreground processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-25781MedSep 30, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

  • CVE-2020-2285MedSep 23, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Liquibase Runner Plugin 1.4.7 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2020-2282MedSep 23, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Implied Labels Plugin 0.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to configure the plugin.

  • CVE-2020-2255MedSep 16, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Blue Ocean Plugin 1.23.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.

  • CVE-2020-13523LowAug 4, 2020
    risk 0.21cvss 3.3epss 0.00

    An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious IRP to trigger this vulnerability.

  • CVE-2020-2202MedJul 2, 2020
    risk 0.21cvss 4.3epss 0.01

    A missing permission check in Jenkins Fortify on Demand Plugin 6.0.0 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins.

  • CVE-2017-18872MedJun 19, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in Mattermost Server before 4.4.3 and 4.3.3. Attackers could reconfigure an OAuth app in some cases where Mattermost is an OAuth 2.0 service provider.